4 ms·
This sounds a lot like "I forgot my ultimate recovery password, but its someone else's fault."
by mmmlinux 1y ago
This sounds a lot like "I forgot my ultimate recovery password, but its someone else's fault."
- bell-cot 1y agoYes. But in general, the way that most humans "naturally expect" such things to work is simply incompatible with the usually-extremely-convenient nature of computer accounts and cloud services.
- throwaway48476 1y agoThen it is too convenient.
- throwaway48476 1y agoA security model that the user does not understand and contains traps is not a good security model.
- Hizonner 1y agoOK, but what model would you suggest? Apple has no adequate way to actually verify who anybody is without (a) forcing them to physically visit one of a small number of offices (it can't be every store), and (b) probably charging a significant fee to cover the cost of doing real verification. And even that demands assuming that the identifying information on the account is right.
- wmf 1y agoThe person in the article who has their whole professional life in a stolen Apple account would probably be happy to visit Apple HQ in person.
- throwaway48476 1y agoFor account recovery in store verification is viable. They're already collected data on their customers via payment processors. I would also force users to watch a video explaining the security features and quiz them before turning them on. You can't expect users to immediately understand how the security model works.
- newsclues 1y agoDigital identity is an essential aspect of modern life. The fact that the government doesn’t have a great standard for identity and it’s left to banks and tech companies is crazy.
- 20after4 1y agoIdentity is a really hard problem to solve. Just about any scheme you can think of to verify identity, some smart criminal can think of a way to exploit or circumvent/abuse the system.
- newsclues 1y agoOh no a hard problem. Too bad we don't have smart people to solve it. You know there are smart criminals who use fake, or fraudulent passports and travel documents? And yet we still go through the process of using them because a system with some control is better than chaos and no control.
- unyttigfjelltol 1y agoYes, this is literally one of a handful of core government functions.
- mingus88 1y agoI have a hard time believing this when they also have Apple Cash and Apple Pay. Even with their strong privacy fundamentals they know more about their account holders than any single business should.
- oarsinsync 1y ago> Apple has no adequate way to actually verify who anybody is without (a) forcing them to physically visit one of a small number of offices (it can't be every store), and (b) probably charging a significant fee to cover the cost of doing real verification. My bank is able to verify me remotely to login to their app from a new device in under 15 minutes, just with a photo of my ID card and a video of my face. And the bank is liable for any losses caused if they misidentify me. Why can my bank do it but apple cant?
- JumpCrisscross 1y ago> Why can my bank do it but apple cant? Banks write off tens of billions of dollars of fraud costs a year. They can do this because money is fungible.
- Hizonner 1y agoYour bank verifies that against the copy of your ID that was collected in person when you opened the account (unless you're using some fly-by-night FinTech "bank", anyway). At a minimum, the bank has already collected, and checked, a bunch of other information that it can use to verify you (more than Apple can collect without mass user rebellion). It has reasonable confidence you haven't lied about that information. The bank can use that information to look up more about you in public records (which the bank knows how to do because, unlike Apple, it doesn't operate in every jurisdiction in the world). And I suspect that the ID/video check is on top of proving you already know a password. Perhaps even more important, the bank knows exactly what liability it's assuming, and what risk it's exposing you to. There's a limit on how much money the app will let you move (even if the bank doesn't tell you what it is). All the transactions you can do are defined by the bank, it knows what's going on at all times, and it can and does apply extra checks for risky-looking transactions. And bank transactions in general have a whole reversal-based security layer on top of all that. On the other hand, people use their Apple accounts to log into God-knows-what third party systems with God-knows-what risks and God-knows-what other security measures or lack thereof. Oh, and also the bank charges you ongoing overt or hidden fees specifically to cover the costs of securing your money. And of insurance if it fails to do so.
- KingInTheFnord 1y agoThey do, they simply choose not to as a business. They should be forced to.
- ghusto 1y ago> OK, but what model would you suggest? I don't know, I'm not a multi-billion dollar multinational organisation employing some of the smartest and highest paid engineers in the world. Off the top of my modest head though, an ID check at one of the thousands of stores they have around the world sound like it could work.
- EA-3167 1y agoIs there a security model that's both highly secure, and foolproof regardless of the mental faculties of potentially billions of diverse users? I think the answer is, "Obviously not," so the real question is whether or not the necessary compromises made here represent acceptable measures.
- throwaway48476 1y agoSecurity requires education. A new purely mechanical lock took two weeks before it was routine.